
CCIE Security
Domain 4Objective 18
4.18 Cisco IBNS 2.0 (C3PL) for Authentication, Access Control, and User Policy Enforcement CCIE-SECURITY Practice Questions (Page 6)
Part of the 4.0 Identity Management, Information Exchange, and Access Control domain, which accounts for 25% of the CCIE-SECURITY exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~13–20 in this domain), expect 1–1 from this objective — we provide 49 practice questions to prepare you well beyond it. (estimate)
49questions here
10free pages
7concepts
25%of the exam
Questions 26–30
- 26
A corporation is deploying IBNS 2.0 and wants to enforce a session timeout and reauthentication for all users after 8 hours. They also want to enforce posture assessment for devices that are not compliant. What is the best way to implement this using C3PL?
Select an answer first - 27
A network administrator is troubleshooting an IBNS 2.0 deployment where users are failing 802.1X authentication. The RADIUS server logs show that authentication requests are being received but are timing out. What is the most likely cause and what should be checked first?
Select an answer first - 28
A company is deploying IBNS 2.0 and wants to enforce different access policies for users based on their role. They have three roles: admin, employee, and guest. They want to assign different VLANs and ACLs to each role. What is the most efficient way to implement this using C3PL?
Select an answer first - 29
A hospital is implementing IBNS 2.0 and wants to enforce a policy that requires reauthentication every 12 hours for all users. They also want to apply a dACL that restricts access to patient records for non-clinical staff. What is the best way to implement this?
Select an answer first - 30
A university is deploying IBNS 2.0 for its dormitory network. The network team wants to automatically authenticate gaming consoles and smart TVs that do not support 802.1X, while still requiring 802.1X for laptops. They plan to use a C3PL policy with a class map that matches on device type. Which authentication method should be configured as the fallback in the policy map for the class matching these non-802.1X devices?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “CCIE-SECURITY” is a trademark of its owner, used for identification only.